Skip to content

chore(deps): Bump the python-runtime group with 4 updates - #176

Merged
DoRmAmMu1997 merged 3 commits into
mainfrom
dependabot/pip/python-runtime-b22453635d
Sep 22, 2026
Merged

DoRmAmMu1997 merged 3 commits into
mainfrom
dependabot/pip/python-runtime-b22453635d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-runtime group with 4 updates: ruff, coverage, pandas-stubs and claude-agent-sdk.

Updates ruff from 0.16.7 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates coverage from 7.16.0 to 7.16.1

Release notes

Sourced from coverage's releases.

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

Changelog

Sourced from coverage's changelog.

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Commits
  • ccbb992 docs: prep for 7.16.1
  • 0697ccc chore: make upgrade
  • 12f3595 chore: bump docker/setup-qemu-action in the action-dependencies group (#2280)
  • 35b58d3 fix: CoverageData.update() can be called twice on an in-memory database. #2279
  • 92e1ce9 chore: bump the action-dependencies group with 4 updates (#2278)
  • bf07310 build: quote var expansion (actionlint SC2086)
  • 3c434f5 quality: use shellcheck-py to get shellcheck in GitHub CI
  • 632f397 build: use .txt instead of .pip, even though it's a stupid extension
  • ffc6a4a test: only run diff-cover on pull requests
  • 33553b3 fix: exclude the case line when an irrefutable case body is excluded (#2269)
  • Additional commits viewable in compare view

Updates pandas-stubs from 3.0.5.260730 to 3.0.5.260914

Commits
  • 6ad02be Version 3.0.5.260914
  • 5533758 Bump pyrefly version (#1945)
  • 711cf2f BLD: temporarily pin pyright to 1.1.411 (#1942)
  • 507243e TST: nightly expect Pandas4Warning for Series.drop/rename inplace and...
  • a09e2ed TYP: align Index subtraction overloads (#1938)
  • 156be75 TST: add focused Period scalar subtraction tests (#1936)
  • 6b84c3a CLN: load tests._typing from pandas-stubs/_typing.pyi without file swap (#1930)
  • 14f8185 TST: add focused Period scalar addition tests (#1933)
  • 0a77a3a TYP: move stub-only helper types to _stubs_only (#1935)
  • a382437 TYP: update stubs for ty 0.0.76 (#1932)
  • Additional commits viewable in compare view

Updates claude-agent-sdk from 0.2.152 to 0.2.154

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.154

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.274

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.154/

pip install claude-agent-sdk==0.2.154

v0.2.153

New Features

  • snapshot option for system prompts: Added a snapshot field to SystemPromptPreset and a new SystemPromptCustom typed dict. When snapshot is True, the session keeps the system prompt recorded on its first request, improving prompt-caching behavior across resumed sessions. When False, the prompt is rebuilt on every request, useful for iterating on append text. Requires CLI 2.1.257+ (#1268)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.273

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.153/

pip install claude-agent-sdk==0.2.153
Changelog

Sourced from claude-agent-sdk's changelog.

0.2.154

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.274

0.2.153

New Features

  • snapshot option for system prompts: Added a snapshot field to SystemPromptPreset and a new SystemPromptCustom typed dict. When snapshot is True, the session keeps the system prompt recorded on its first request, improving prompt-caching behavior across resumed sessions. When False, the prompt is rebuilt on every request, useful for iterating on append text. Requires CLI 2.1.257+ (#1268)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.273
Commits
  • 9d398b6 docs: update changelog for v0.2.154
  • 2a5bdcc chore: release v0.2.154
  • efcd177 chore: bump bundled CLI version to 2.1.274
  • 763922b docs: update changelog for v0.2.153
  • f706bfb chore: release v0.2.153
  • 0fc0940 chore: bump bundled CLI version to 2.1.273
  • e773e44 Add snapshot option to system_prompt (#1268)
  • 46fe65f ci: raise the PyPI pre-flight threshold to 49.5 GiB for now (#1267)
  • be6d116 test: use the haiku alias in test_set_model (#1266)
  • b39b656 chore: bump bundled CLI version to 2.1.272
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-runtime group with 4 updates: [ruff](https://github.com/astral-sh/ruff), [coverage](https://github.com/coveragepy/coveragepy), [pandas-stubs](https://github.com/pandas-dev/pandas-stubs) and [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python).


Updates `ruff` from 0.16.7 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.8)

Updates `coverage` from 7.16.0 to 7.16.1
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.1)

Updates `pandas-stubs` from 3.0.5.260730 to 3.0.5.260914
- [Changelog](https://github.com/pandas-dev/pandas-stubs/blob/main/docs/release_procedure.md)
- [Commits](pandas-dev/pandas-stubs@v3.0.5.260730...v3.0.5.260914)

Updates `claude-agent-sdk` from 0.2.152 to 0.2.154
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.152...v0.2.154)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: coverage
  dependency-version: 7.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: pandas-stubs
  dependency-version: 3.0.5.260914
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.154
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 20, 2026
@DoRmAmMu1997
DoRmAmMu1997 self-requested a review September 21, 2026 07:35

@DoRmAmMu1997 DoRmAmMu1997 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

Dependabot bumps the requirement files and cannot see the second assertions
that exist so a version cannot move without a human reading the release notes.
Two tests were red on the bump; both are now green for reasons written down
rather than asserted.

  ruff            0.16.7        -> 0.16.8          + .pre-commit-config.yaml
  coverage        7.16.0        -> 7.16.1          (no second assertion)
  pandas-stubs    3.0.5.260730  -> 3.0.5.260914
  claude-agent-sdk 0.2.152      -> 0.2.154

RUFF. The hook rev is bumped with it, which is the whole point of
test_precommit_ruff_rev_matches_the_requirements_dev_pin. 0.16.8 changes ten
rules; every one of them is either unselected here or has zero trigger sites in
this tree. We select E,W,F,I,B,UP,C4,SIM,RUF at target-version py312, so:
flake8-type-checking's TC001/2/3 change is unselected AND gated on Python 3.15;
PTH103 is unselected. Of the selected ones, SIM117's new nested-`async with`
detection finds nothing (the repo contains no `async with` at all), UP035's
ByteString change nothing, UP040/046/047 nothing (no TypeVarTuple, no
ParamSpec) and they narrow output rather than widen it, RUF043 nothing (none of
the 95 `pytest.raises(match=)` sites uses `\Z`), RUF064's parent_mode nothing.
Not left as changelog reading: 0.16.8 was installed in isolation and RUN over
this exact post-merge tree -- all checks passed, same as 0.16.7.

COVERAGE. Two bug fixes. The `case _:` exclusion fix cannot change anything we
measure: the repo has no `case _:` anywhere. The other is CoverageData.update()
on an in-memory database, which the gate does not use. Effectively a no-op
here. NOTE: coverage is the one pin in this group with NO second assertion, so
this bump could have gone green with nobody reading it -- exactly the hole the
numpy comment in this file describes. Flagged for the operator rather than
closed unilaterally, since adding an assertion is a policy change, not a bump.

PANDAS-STUBS. The pandas release being described does not move (3.0.5 both
sides), so the matching-majors reason this pin exists for is untouched; only
the stub snapshot advances. Typing-only, so it was verified BEFORE the merge:
mypy checks all 80 source files against 3.0.5.260914 with ZERO errors in repo
code. The upstream change that could have reached us is "move stub-only helper
types to _stubs_only" (#1935), and nothing here imports `pandas._typing` or
`_stubs_only`. The comment records how to repeat that run and warns that
staging stubs on MYPYPATH makes mypy analyse the stub package itself and report
~24 errors inside it -- an artifact, not a signal.

CLAUDE-AGENT-SDK. 0.2.154 is a bundled-CLI bump only. 0.2.153 is the only one
with a Python surface: a `snapshot` field on `SystemPromptPreset` and a new
`SystemPromptCustom` TypedDict, both additive and both on the PRESET form of
system_prompt. We never use that form -- `_system_prompt_as_file` passes the
FILE form because the prompt is far past Windows' 32,767-character command-line
limit -- so it cannot reach this agent even as a default. What actually moved
is the bundled CLI, 2.1.259 -> 2.1.274, which is the part running the agent and
which CI never spawns. Standing check unchanged: confirm on the next PAPER
session that decisions still return ("SLHuntingAgent decision cost ~$..."). If
they stop, revert this pin first.

origin/main is merged in so CI validates the state that will actually land,
which matters here because a ruff minor can flag code that reached main after
Dependabot cut the branch.

Negative-tested 5 ways, all 5 caught: reverting either bumped pin, leaving the
ruff hook behind, moving the ruff requirement ahead of the hook, and loosening
a pin from == to >=. The control is the finding above -- silently reverting
coverage still PASSES, which is what makes the missing assertion real rather
than theoretical.

Gates: 606 master, 28 market-data-health, 1580 pytest, ruff 0.16.8 (the new
pin), mypy (80 files), compileall, bandit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@DoRmAmMu1997
DoRmAmMu1997 merged commit 6bbf7e3 into main Sep 22, 2026
7 of 8 checks passed
@DoRmAmMu1997
DoRmAmMu1997 deleted the dependabot/pip/python-runtime-b22453635d branch September 22, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant